Anonymous
2026-09-06 20:27:09
(1 hour ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x)
Port Scan
🇧🇪
cmbplf
2026-09-06 19:48:14
(2 hours ago)
104 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-09-06 19:16:00
(3 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
Mangelot Hosting
2026-09-06 16:44:42
(5 hours ago)
(modsecurity) srv101 ModSecurity 34.62.143.87 (BE/Belgium/87.143.62.34.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv101 ModSecurity 34.62.143.87 (BE/Belgium/87.143.62.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:11:40
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:11:32.808357 2026] [security2:error] [pid 27288:tid 27288] [client 34.62.143.87:48304] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aroilcontrolsystem.com|F|2"] [data ".aroilcontrolsystem.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aroilcontrolsystem.com"] [uri "/z9x8c7v6b5-debug-trigger-www.aroilcontrolsystem.com"] [unique_id "ap2QtKOwEOSLHdVRcS2rQAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-06 15:56:38
(6 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.62.143.87 (BE/Belgium/87.143.62.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.62.143.87 (BE/Belgium/87.143.62.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.62.143.87 - - [06/Sep/2026:17:56:36 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 200 4743 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "34.62.143.87" host=www.vortici.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 15:46:19
(6 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:46:12.102081 2026] [security2:error] [pid 1695:tid 1695] [client 34.62.143.87:50014] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||robtown.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "robtown.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap2KxHCVwZIDtQ3Y1Ka-rwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:09:14
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:09:08.023130 2026] [security2:error] [pid 24201:tid 24201] [client 34.62.143.87:46020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||armorcorp.gulftelecom.com|F|2"] [data ".gulftelecom.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "armorcorp.gulftelecom.com"] [uri "/z9x8c7v6b5-debug-trigger-armorcorp.gulftelecom.com"] [unique_id "ap2CFNsi6xQjRS6RLa_1owAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
gamabe
2026-09-06 14:09:59
(8 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
🇬🇧
gws-hostmaster
2026-09-06 13:45:55
(8 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 10): HTTP header is restricted by policy (/x-middleware-subreq ...
show more
ModSecurity OWASP CRS (Anomaly Score: 10): HTTP header is restricted by policy (/x-middleware-subrequest/);Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack
Anonymous
2026-09-06 13:32:29
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
maxpower
2026-09-06 13:07:14
(9 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.62.143.87 (BE/Belgium/87.143.62.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.62.143.87 (BE/Belgium/87.143.62.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.62.143.87 - - [06/Sep/2026:15:07:11 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/2.0" 200 4775 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "34.62.143.87" host=archivio.vortici.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-06 13:07:05
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.62.143.87 (87.143.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:06:56.453310 2026] [security2:error] [pid 5891:tid 5891] [client 34.62.143.87:45894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ipostsocialmedia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ipostsocialmedia.com"] [uri "/z9x8c7v6b5-debug-trigger-ipostsocialmedia.com"] [unique_id "ap1lcDMo9M7ymkMcTlVR4AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 12:12:40
(10 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /rclone.conf (+4 more) | 2026-09-06 12:12 UTC
show less
Hacking
Web App Attack
🇩🇪
verlon
2026-09-06 10:43:04
(11 hours ago)
2026/09/06 12:43:00 [error] 1134502#1134502: *453373 access forbidden by rule, client: 34.62.143.87, ...
show more
2026/09/06 12:43:00 [error] 1134502#1134502: *453373 access forbidden by rule, client: 34.62.143.87, server: digelstorebudapest.hu, request: "GET /.git-credentials HTTP/2.0", host: "digelstorebudapest.hu"
2026/09/06 12:43:00 [error] 1134502#1134502: *453373 access forbidden by rule, client: 34.62.143.87, server: digelstorebudapest.hu, request: "GET /.gitconfig HTTP/2.0", host: "digelstorebudapest.hu"
2026/09/06 12:43:01 [error] 1134502#1134502: *453373 access forbidden by rule, client: 34.62.143.87, server: digelstorebudapest.hu, request: "GET /.gitlab-ci.yml HTTP/2.0", host: "digelstorebudapest.hu"
...
show less
Hacking
Web App Attack